First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Services/Shadow IT Assessment Workshop (Remote)
Training

Shadow IT Assessment Workshop (Remote) — Cloud App Discovery & Control

Shadow IT Assessment Workshop (Remote) is a 2-day remote training engagement for organizations that want to discover and assess cloud applications and services being used without the IT department’s knowledge. IT Partner uses Microsoft Cloud App Security to evaluate cloud app usage from the organization’s network and provides findings, recommendations, and a prioritized Cloud Usage Visibility and Control Road Map. SKU: ITPWW180TRNOT. Price: $1,900. Duration: 2 days. Manager: Mike Mackey.

Timeline 2 daysService owner Mike MackeyOffice 365microsoft 365

What this engagement is

Shadow IT refers to applications and infrastructure that are managed and used without the enterprise IT department’s knowledge. This remote workshop helps customers discover Shadow IT by using Microsoft Cloud App Security to evaluate cloud application and service usage from within the organization’s network. The engagement focuses on understanding the customer’s cloud security objectives, comparing them with actual cloud usage, and producing findings and recommendations for improving visibility and control. This service is listed for Office 365 and Microsoft 365 as Training. Source page date: 2019-03-14.

Success criteria

01Deliver the Shadow IT Assessment, including good security principles covering people, process, and technology solutions.
02Improve the security posture when it comes to usage of cloud applications and services.
03Base the assessment on the discovery of usage of cloud applications and services.

What you receive

Kickoff Presentation: an overview of the engagement covering vision and objectives, requirements, and next steps.
Pre-Assessment Questionnaire: a questionnaire containing questions on cloud usage/adoption, security requirements and objectives, regulations, and frameworks.
Shadow IT Discovery Report: a document containing a list of discovered possible Shadow IT usage and recommendations for further investigation.
Cloud Usage Visibility and Control Road Map: a prioritized, actionable road map for addressing discovered cloud usage, especially its Shadow IT aspect, including mapping capabilities of Cloud App Security in a customer environment.

How the work unfolds

Remote kickoff meeting

The Shadow IT Assessment typically consists of an up to two-hour remote kickoff meeting followed by remote assessment workshops. The kickoff includes an introduction to the engagement covering objectives, flow, responsibilities, and governance, and IT Partner provides and explains the pre-assessment questionnaire to the customer.

Webinar 1 — Education & Setup

Review the questionnaire, which should be ready by the time of the webinar, to get mutual understanding, especially around the customer’s cloud usage and associated security objectives and requirements. Provide education and readiness on Microsoft Cloud App Security.

Webinar 2 — Exploration & Discovery

Review the CAS report(s) with the customer, explore specific use cases of cloud usage in the portal, create the final report from the engagement highlighting discovered cases of Shadow IT, and create the Cloud Usage Visibility and Control Road Map.

Webinar 3 — Review & Road Map

Present and discuss the final report from the engagement, highlighting discovered cases of Shadow IT, meaning usage of unapproved cloud applications or services. Review the Cloud Usage Visibility and Control Road Map.

Prerequisites

Microsoft 365 tenant and Microsoft Cloud App Security service. Either customer production Microsoft 365 tenant with CAS through E5 license or trial Microsoft 365 tenant and CAS trial for up to 30 days.
Access to logs from customer firewalls or proxies.
Log Collector should be configured and ready to work. More info: https://docs.microsoft.com/en-us/cloud-app-security/discovery-docker

Who does what

IT Partner

  • Gain an understanding of customer's cloud security objectives and requirements toward cloud usage and verify them against real usage of cloud applications and services
  • Provide guidance, recommendations, and best practices on how to successfully use Microsoft Cloud App Security (CAS) to mitigate security threats that are associated with usage of cloud application and services
  • Provide a prioritized and actionable road map for the customer, containing proposed actions based on user impact and implementation cost
  • Map Microsoft CAS capabilities and partner services to assessment findings, taking into account customer's security objectives and requirements

Your team

  • Information: This includes accurate, timely (within three business days or as mutually agreed upon), and complete information
  • Access to people: This includes access to knowledgeable customer personnel, including business user representatives, and access to funding (if additional budget is needed to deliver project scope), as well as access to knowledgeable personnel who manage the firewalls, can provide credentials for log extraction, and can alter firewall rules if necessary.
  • Access to systems: This includes access to all necessary customer work locations, networks, systems, and applications (remote and onsite)

What's not included

Remediation or enforcement of Shadow IT findings, including blocking applications, creating conditional access controls, or implementing sanction/unsanction policies.
Production deployment, tuning, or long-term operation of Microsoft Cloud App Security beyond the assessment and workshop activities described.
Procurement of Microsoft 365, Microsoft Cloud App Security, E5 licenses, trial subscriptions, firewall/proxy products, or any third-party tools.
IT Partner performing firewall, proxy, network, endpoint, or identity infrastructure changes; the customer may still need to make log collection or access-related changes if necessary for the assessment.
Custom connectors, custom data engineering, SIEM integration, SOC runbook development, or automated remediation workflow development.
Comprehensive security architecture review, penetration testing, compliance audit, legal review, data classification program, or full cloud governance implementation.
Investigation of every individual user action or application transaction; findings are based on available discovery data, logs, and workshop analysis.
Ongoing managed security monitoring, incident response, alert triage, or post-workshop administration unless contracted separately.

Limitations & technical notes

!An onsite form of the workshop is available at https://o365hq.com/eu/license/ITPWW160TRNOT.

Frequently asked questions

What is the Shadow IT Assessment Workshop (Remote)?

The Shadow IT Assessment Workshop (Remote) is a 2-day remote training engagement that helps organizations discover and assess cloud applications and services being used without the IT department’s knowledge. IT Partner uses Microsoft Cloud App Security to evaluate cloud app usage from the organization’s network and provides findings, recommendations, and a prioritized Cloud Usage Visibility and Control Road Map.

Who is this Shadow IT Assessment Workshop intended for?

This workshop is intended for organizations using Office 365 or Microsoft 365 that want better visibility and control over unapproved or unknown cloud application usage. It is especially relevant when IT leaders need to compare cloud security objectives with actual cloud usage discovered from network activity.

How long does the Shadow IT Assessment Workshop take?

The Shadow IT Assessment Workshop is a 2-day remote engagement. The stated plan includes a remote kickoff meeting and remote assessment webinars covering education, setup, exploration, discovery, final report review, and the road map.

How much does the Shadow IT Assessment Workshop cost?

The listed price for the Shadow IT Assessment Workshop (Remote) is $1,900. The service SKU is ITPWW180TRNOT, and any commercial details beyond the listed fixed price should be confirmed directly with IT Partner.

What deliverables are included in the Shadow IT Assessment Workshop?

The workshop includes a kickoff presentation, a pre-assessment questionnaire, a Shadow IT Discovery Report, and a Cloud Usage Visibility and Control Road Map. The discovery report lists possible Shadow IT usage and recommendations for further investigation, while the road map prioritizes actions for improving cloud usage visibility and control.

What is the Cloud Usage Visibility and Control Road Map?

The Cloud Usage Visibility and Control Road Map is a prioritized, actionable plan for addressing discovered cloud usage, especially usage that appears to be Shadow IT. It maps Microsoft Cloud App Security capabilities to the customer environment and recommends actions based on user impact and implementation cost.

What happens during the remote kickoff meeting?

The remote kickoff meeting typically lasts up to two hours and introduces the engagement objectives, flow, responsibilities, and governance. IT Partner also provides and explains the pre-assessment questionnaire so the customer can supply information about cloud adoption, security requirements, regulations, and frameworks.

What happens in the assessment webinars?

The workshop webinars cover education and setup, exploration and discovery, and review of the final report and road map. IT Partner reviews the questionnaire, provides readiness on Microsoft Cloud App Security, reviews Cloud App Security reports with the customer, explores cloud usage use cases, and presents discovered Shadow IT findings.

What prerequisites are required before the Shadow IT Assessment Workshop?

The customer needs a Microsoft 365 tenant and Microsoft Cloud App Security, either through a production Microsoft 365 tenant with CAS via an E5 license or a trial Microsoft 365 tenant with a CAS trial for up to 30 days. The customer also needs access to firewall or proxy logs and should have the Log Collector configured and ready to work.

Does the workshop require Microsoft Cloud App Security?

Yes, Microsoft Cloud App Security is a prerequisite because the assessment uses it to evaluate cloud application and service usage from the organization’s network. The service scope states that the customer can use CAS through an E5 license or use a trial Microsoft 365 tenant and CAS trial for up to 30 days.

What network or log access is needed for the assessment?

The assessment requires access to logs from customer firewalls or proxies because those logs support discovery of cloud application and service usage. The customer should also have the Log Collector configured and ready, and knowledgeable firewall personnel may need to provide credentials for log extraction or adjust firewall rules if necessary.

What are IT Partner’s responsibilities during the workshop?

IT Partner is responsible for understanding the customer’s cloud security objectives, comparing them with real cloud application and service usage, and providing guidance on Microsoft Cloud App Security. IT Partner also provides findings, recommendations, best practices, and a prioritized road map that maps CAS capabilities and partner services to the assessment findings.

What are the client’s responsibilities during the workshop?

The client is responsible for providing accurate, complete, and timely information, typically within three business days or as mutually agreed. The client must also provide access to knowledgeable personnel, including business representatives and firewall administrators, plus access to required systems, networks, applications, and logs.

Will the Shadow IT Assessment Workshop cause downtime or user disruption?

The service description does not state that the workshop requires planned downtime, because it is a remote assessment based on Microsoft Cloud App Security, questionnaires, and firewall or proxy log analysis. However, any operational impact from log collection, firewall access, or configuration changes should be confirmed with IT Partner and the customer’s network team before the engagement.

Does the workshop block or remove Shadow IT applications?

The stated scope focuses on discovery, assessment, reporting, recommendations, and a prioritized road map; it does not state that IT Partner will block, remove, or remediate Shadow IT applications during the 2-day workshop. If enforcement actions or application controls are required, they should be discussed separately with IT Partner.

What does the Shadow IT Discovery Report include?

The Shadow IT Discovery Report contains a list of discovered possible Shadow IT usage and recommendations for further investigation. Its purpose is to highlight cloud applications and services that may be unapproved or unknown to IT, based on the assessment of cloud usage data.

What outcomes should we expect from the workshop?

Expected outcomes include completion of the Shadow IT Assessment, improved understanding of cloud application and service usage, and recommendations that support better visibility and control. The success criteria include applying good security principles across people, process, and technology and basing the assessment on discovered cloud application and service usage.

What happens after the Shadow IT Assessment Workshop is completed?

After completion, the customer receives the final report and the Cloud Usage Visibility and Control Road Map for prioritizing next steps. The road map is intended to guide follow-up actions, but the source scope does not state that implementation of those actions is included in the 2-day workshop.

Is an onsite version of the Shadow IT Assessment Workshop available?

Yes, the service notes that an onsite form of the workshop is available separately. The listed service described here is the remote version of the Shadow IT Assessment Workshop.

What is not included in the Shadow IT Assessment Workshop?

The source service description does not list specific out-of-scope items or additional-cost items. Based on the stated scope, buyers should treat the engagement as a 2-day remote assessment and training workshop with reporting and a road map, and should confirm any remediation, deployment, or enforcement work separately with IT Partner.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$1,900
2 days
Book a meeting